7.8

CVE-2021-30309

Improper size validation of QXDM commands can lead to memory corruption in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

Data is provided by the National Vulnerability Database (NVD)
QualcommMdm9650 Firmware Version-
   QualcommMdm9650 Version-
QualcommQca6174a Firmware Version-
   QualcommQca6174a Version-
QualcommQca6390 Firmware Version-
   QualcommQca6390 Version-
QualcommQca6391 Firmware Version-
   QualcommQca6391 Version-
QualcommQca9377 Firmware Version-
   QualcommQca9377 Version-
QualcommQcm6125 Firmware Version-
   QualcommQcm6125 Version-
QualcommQcs410 Firmware Version-
   QualcommQcs410 Version-
QualcommQcs603 Firmware Version-
   QualcommQcs603 Version-
QualcommQcs605 Firmware Version-
   QualcommQcs605 Version-
QualcommQcs610 Firmware Version-
   QualcommQcs610 Version-
QualcommQcs6125 Firmware Version-
   QualcommQcs6125 Version-
QualcommSd660 Firmware Version-
   QualcommSd660 Version-
QualcommSd665 Firmware Version-
   QualcommSd665 Version-
QualcommSd690 5g Firmware Version-
   QualcommSd690 5g Version-
QualcommSd730 Firmware Version-
   QualcommSd730 Version-
QualcommSd765 Firmware Version-
   QualcommSd765 Version-
QualcommSd765g Firmware Version-
   QualcommSd765g Version-
QualcommSd768g Firmware Version-
   QualcommSd768g Version-
QualcommSd865 5g Firmware Version-
   QualcommSd865 5g Version-
QualcommSd870 Firmware Version-
   QualcommSd870 Version-
QualcommSdx12 Firmware Version-
   QualcommSdx12 Version-
QualcommSdx55m Firmware Version-
   QualcommSdx55m Version-
QualcommSdxr1 Firmware Version-
   QualcommSdxr1 Version-
QualcommSm7250p Firmware Version-
   QualcommSm7250p Version-
QualcommWcd9326 Firmware Version-
   QualcommWcd9326 Version-
QualcommWcd9335 Firmware Version-
   QualcommWcd9335 Version-
QualcommWcd9341 Firmware Version-
   QualcommWcd9341 Version-
QualcommWcd9370 Firmware Version-
   QualcommWcd9370 Version-
QualcommWcd9375 Firmware Version-
   QualcommWcd9375 Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommWcd9385 Firmware Version-
   QualcommWcd9385 Version-
QualcommWcn3950 Firmware Version-
   QualcommWcn3950 Version-
QualcommWcn3980 Firmware Version-
   QualcommWcn3980 Version-
QualcommWcn3988 Firmware Version-
   QualcommWcn3988 Version-
QualcommWcn3990 Firmware Version-
   QualcommWcn3990 Version-
QualcommWcn3991 Firmware Version-
   QualcommWcn3991 Version-
QualcommWcn3998 Firmware Version-
   QualcommWcn3998 Version-
QualcommWcn6850 Firmware Version-
   QualcommWcn6850 Version-
QualcommWcn6851 Firmware Version-
   QualcommWcn6851 Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8815 Firmware Version-
   QualcommWsa8815 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.152
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
product-security@qualcomm.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.